Hello,
I am thinking about using Hercules CPU with lock-step for a new safety development (SIL3) but I would need some clarifications.
Regarding the inputs for getting a SIL3 certification redundancy in the input is needed so in the case of using two cpus the signal from one sensor is connected to both CPU who have similar SW and are controlling the signal.
As far as I know with in this kind of Safety CPUs the safety functions are programmed only in one core and the second core is just checking that the first one is running the instructions properly. So my doubts are:
1.- How do you manage one input which a SIL3 required with only one core? Is this possible?
2.- Is it enough for SIL2/SIL3 programming the safety functions only in one core instead two SW in two CPU as it has been done before? Am I missing something?
Maybe someone has already certify some SIL2/SIL3 product using this architecture and could help me out!
Thanks and best regards,